Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-84156
HistoryDec 01, 2022 - 12:00 a.m.

QEMU Buffer Overflow Vulnerability (CNVD-2022-84156)

2022-12-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
qemu
buffer overflow
validation
input data
acpi error record serialization table
exploited
malicious attackers
crash
host process

0.001 Low

EPSS

Percentile

19.0%

QEMU (Quick Emulator) is a set of emulation processor software by Fabrice Bellard, a French personal developer. The software is fast and cross-platform. QEMU suffers from a buffer overflow vulnerability that stems from a lack of validation of the input data size or length in the read_erst_record() and write_erst_record() functions of the ACPI Error Record Serialization Table (ERST) device, which can be exploited by malicious attackers to crash the QEMU process on the host to crash.

CPENameOperatorVersion
qemu qemueq7.0.0